Encryption at rest
AES-256 for all customer databases. Keys managed via KMS with periodic rotation.
Built from day one to pass enterprise security reviews. Here is what is under the hood, and what we are working on next.
The controls a security review team looks for during vendor evaluation, live in the platform right now.
AES-256 for all customer databases. Keys managed via KMS with periodic rotation.
TLS 1.3 for external connections. Internal services run on an isolated private network. Certificates auto-rotated by Let's Encrypt.
Hard data boundaries at organization level. Every query is constrained to the active org from the JWT.
JWT RS256, public JWKS for verification. No shared secrets, no duplicated identity DBs.
Every sensitive action is logged, who, when, which resource. Searchable, exportable.
Available for every product. Data stays on EU servers in Frankfurt. Sovereign deployment adds full isolation for strict residency needs.
Private cloud or air-gapped on-premise for customers with strict residency requirements. Contact us.
Data export (Article 20) and deletion (Article 17) ship in every account. No ticket needed.
A check means shipped today. A half mark means in progress with a target date. No enterprise-ready claims for things that have not shipped yet.
If you discover a security vulnerability, we want to hear from you. Send details to contact@amargicreative.com. We will respond within 48 hours with an acknowledgment and remediation timeline. We credit researchers who report responsibly and follow coordinated disclosure.
AES-256 for all customer databases at rest, with KMS-managed keys and periodic rotation. TLS 1.3 for external connections in transit; internal services run on an isolated private network. Certificates managed by Let's Encrypt + ACME.
Hard data boundaries at organization level. Every database query is constrained to the active org from the JWT, one product cannot read another product's data without explicitly going through Amargi Workspace.
EU data residency is the default for every product (Hetzner, Frankfurt). Customers requiring residency in a different region or full self-hosting can use sovereign deployment options, private cloud or air-gapped on-premise.
Not yet. SOC 2 Type II certification is targeted for Q2 2027 and ISO 27001 for H2 2027. We do not make enterprise-ready claims for things that have not shipped, this is candid status, not aspirational.
Email contact@amargicreative.com. We respond within 48 hours with an acknowledgment and remediation timeline. We credit researchers who report responsibly and follow coordinated disclosure.
Contact us, we provide security questionnaires, architecture documents, and sovereign-deployment details on request.